Live data from Hacker News

Smaug, the brand new OVHcloud backbone network infrastructure

ovh.com

11–20 of 32 posts

Re: Smaug, the brand new OVHcloud backbone network infrastructure

#12

What they describe sounds to me exactly like standard architecture for combining PoPs and peering with backbone providers. What am I missing?

Nothing really, they were on worse designs for years and they came to a point that it couldn’t scale, so they had to come up with a new proper design

Re: Smaug, the brand new OVHcloud backbone network infrastructure

#13

OVH Hardware, support and pricing is GREAT! Buuuuutttttt... Their firewall situation is not. Guess what, if you use the supplied firewall, any server from any other customer in the local NOC that your server is in, can connect to your server. They seem to be all "safely" behind the OVH firewall product. You have to protect each server individually with its own in-machine firewall. I don't want to automatically trust…

That's not really even a firewall issue, just a very poorly configured network. Pretty shameful for a provider of their size.

Re: Smaug, the brand new OVHcloud backbone network infrastructure

#14

OVH Hardware, support and pricing is GREAT! Buuuuutttttt... Their firewall situation is not. Guess what, if you use the supplied firewall, any server from any other customer in the local NOC that your server is in, can connect to your server. They seem to be all "safely" behind the OVH firewall product. You have to protect each server individually with its own in-machine firewall. I don't want to automatically trust…

Can this be mitigated by using something like ufw and restricting the IP access?

Re: Smaug, the brand new OVHcloud backbone network infrastructure

#15

OVH Hardware, support and pricing is GREAT! Buuuuutttttt... Their firewall situation is not. Guess what, if you use the supplied firewall, any server from any other customer in the local NOC that your server is in, can connect to your server. They seem to be all "safely" behind the OVH firewall product. You have to protect each server individually with its own in-machine firewall. I don't want to automatically trust…

> You have to protect each server individually with its own in-machine firewall.

That's the standard practice?

OVH's own firewall is for DDoS/DoS protection, not for fine-grained security, did I understand OVH's information incorrectly?

Re: Smaug, the brand new OVHcloud backbone network infrastructure

#16

OVH Hardware, support and pricing is GREAT! Buuuuutttttt... Their firewall situation is not. Guess what, if you use the supplied firewall, any server from any other customer in the local NOC that your server is in, can connect to your server. They seem to be all "safely" behind the OVH firewall product. You have to protect each server individually with its own in-machine firewall. I don't want to automatically trust…

Because I was thinking about OVHCloud, they dont have an VPN with private IPs? And load balancers like AWS/Digital Ocean?

Re: Smaug, the brand new OVHcloud backbone network infrastructure

#17
post #14

OVH Hardware, support and pricing is GREAT! Buuuuutttttt... Their firewall situation is not. Guess what, if you use the supplied firewall, any server from any other customer in the local NOC that your server is in, can connect to your server. They seem to be all "safely" behind the OVH firewall product. You have to protect each server individually with its own in-machine firewall. I don't want to automatically trust…

Can this be mitigated by using something like ufw and restricting the IP access?

That is what the OP said to do in his post.

Re: Smaug, the brand new OVHcloud backbone network infrastructure

#18

Just a reminder, from Wikipedia ( https://en.wikipedia.org/wiki/OVH#Email_spam ): As of November 2019, OVH is listed by The Spamhaus Project as the world's second worst Internet service provider for the proliferation of unsolicited bulk E-Mail https://www.spamhaus.org/sbl/listings/ovh.net Looking at the same list now, it recently seems to have added fraud, and many malware distribution entries too.

I can't speak to reports but I can testify about server logs. OVH IPs have been a top source of spam and attacks against my (US) (If a firewall goes offline for 60 seconds, I will get hammered from OVH/DO networks. Not exclusively but they're the standout kings. Just think Psychz networks, but scaled up.

I know OVH's size plays into that. But size here is less about the number of net blocks and more about their bureaucratic disinterest in abuse (common to larger hosts, inc hosts I like).

There are comparable sized hosts in the US (AWS, Azure) but when it comes to crapty traffic, OVH makes them look small and insignificant[1].

Unlike moderation at scale, known attacks are often qualifiable, detectable patterns. Can we please care enough to notice & maybe eventually, one day interrupt them?

[1]disclaimer: Spam from Google/Azure & malicious SMTP traffic from AWS totally dominated the first ½ of this year. IDK why. It's since died off - which differentiates them from OVH/DO.

Re: Smaug, the brand new OVHcloud backbone network infrastructure

#19

I had the worst experience from a vps/dedicated hosting provider with OVH few years back, long story short I had a dedicated server with software raid, after a month, one of the disks failed I gave them all the details SN of the disk at fault etc, but apparently the removed the good disk and I lost the server, I asked them to put it back and they told me they had destroyed it, luckily I had backup. Lastly I asked for…

Amazon did about the same exact thing to me a while back, so you're not alone and it's not just cheap hosts that make that mistake as we spent 10k/mo on support alone. (AWS had EBS silently fail which is awful enough but then restored data from the 'bad leg' of the system and lost all. To this day I've never trusted them again - maybe I should get over it but, would you?

Re: Smaug, the brand new OVHcloud backbone network infrastructure

#20
post #4

Just a reminder, from Wikipedia ( https://en.wikipedia.org/wiki/OVH#Email_spam ): As of November 2019, OVH is listed by The Spamhaus Project as the world's second worst Internet service provider for the proliferation of unsolicited bulk E-Mail https://www.spamhaus.org/sbl/listings/ovh.net Looking at the same list now, it recently seems to have added fraud, and many malware distribution entries too.

This is like saying Google is the search engine with the most links to malware pages. 36 IPs is nothing given how big ovh is.

Those entries aren't all singular IP addresses. Some are ranges (etc).

Picking one at random:

https://www.spamhaus.org/sbl/query/SBL492369

That's showing a fair number of IPs.

Post reply on HN